Org Audit
Review department access dashboards and spot employees with governance risks — orphaned accounts from departed staff, excessive permissions that violate least privilege, and segregation of duties conflicts that no one caught. Submit your findings before the audit deadline.
Ready to play?
Put your awareness to the test. See if you can spot the threats before it's too late.
Launch GameWhy This Matters
Periodic access audits are a cornerstone of compliance frameworks — SOX, SOC 2, ISO 27001, and NIST all require regular review of who has access to what. But most organizations treat audits as paperwork rather than security controls, running them quarterly at best and delegating them to managers who lack the context to spot problems.
The most dangerous audit findings are also the easiest to miss. Segregation of duties violations — where one person holds permissions that should require two — are invisible without cross-referencing role definitions. Orphaned accounts from terminated employees persist because offboarding processes fail silently. Excessive permissions accumulate because it's easier to add access than remove it.
Effective access audits require pattern recognition: comparing what access someone has against what their role requires, checking whether terminated employees still have active accounts, and verifying that no single person holds conflicting privileges. The goal isn't perfect access — it's finding the gaps that create real risk.
What You'll Learn
Identify segregation of duties violations by cross-referencing employee permissions against role requirements
Spot orphaned accounts belonging to departed or transferred employees
Recognize excessive permissions that violate the principle of least privilege
Practice systematic audit methodology — scanning for patterns rather than reviewing individual permissions in isolation